CISA KEV Alert 8/31/2026, 4:22:02 PM

CISA warns of critical PaperCut NG/MF flaw CVE-2026-82078

Developing story vulnerability 7 articles tracked
PaperCut NG/MF zero‑day flaws CVE-2026-81578 and CVE-2026-82078 exploited
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-82078 to its Known Exploited Vulnerabilities (KEV) catalogue. The entry concerns PaperCut’s NG/MF product and is titled PaperCut NG/MF Unsafe Reflection Vulnerability. The flaw allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode that resides on the application classpath, running under the security context of the PaperCut server process.

The vulnerability is an unsafe reflection issue that can be triggered remotely, enabling the execution of attacker‑supplied code and the alteration of server settings. It carries a CVSS v3.1 score of 9.4, rating it as critical. At the time of writing, no patch has been published and the vendor has not released an advisory; mitigation must be sought from PaperCut’s guidance.

Active exploitation has been observed, which is the basis for the KEV designation. No public linkage to ransomware campaigns has been reported. CISA has set a remediation deadline of 14 September 2026 for federal agencies to address the issue.

CISA directs Federal Civilian Executive Branch (FCEB) agencies to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Agencies should follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and adhere to BOD 26‑04 patching guidelines. All other organisations are advised to review their PaperCut NG/MF deployments for exposure and apply any available mitigations.

For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-82078 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline